A package can look like a working payment SDK and still be a secret harvester. That is the break here: the fake client returns normal-looking results, which buys time to pull API keys and tokens from developer machines and CI runners before anyone notices the package is bogus.
Socket found 17 malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs. Multiple npm packages shipped malicious versions 1.0.0 through 1.0.3, and the payload stole developer credentials and exfiltrated them to AWS.
Removing the package does not undo the exposure. Any build or dev environment that installed one of these typosquats may already have leaked reusable secrets that can reach payment and cloud integrations downstream.